CVE-2026-15588 on CTRL-OS 26.05
Aliases: CVE-2026-15588
Packages: glib
Status: In Progress
Advisory Information
A denial-of-service and resource exhaustion vulnerability exists within the
GDBuscomponent of GLib. Thegdbusauthauthentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
Updates
2026-08-11 03:15 CEST
Metadata changes:
- Status for package
glib: “In Progress” (2db44e0fa7643c771550997376a6e6b68195b3de)
2026-08-11 03:15 CEST
Metadata changes:
- Status for package
glib: “Plausible”
2026-08-11 03:14 CEST
Metadata changes:
- Status for package
glib: “New”